-
Notifications
You must be signed in to change notification settings - Fork 0
104 lines (81 loc) · 2.72 KB
/
Copy pathci_check.yml
File metadata and controls
104 lines (81 loc) · 2.72 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
name: CI Check
on:
push:
branches: [master]
pull_request:
types: [opened, synchronize]
merge_group:
types: [checks_requested]
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
ci-check:
name: CI Check
runs-on: [self-hosted, codex]
timeout-minutes: 20
permissions:
contents: read
steps:
- uses: actions/checkout@v5
with:
persist-credentials: false
# Contract tests inspect the immutable in-repository action revision
# used by distributed workflows, so its commit must be available.
fetch-depth: 0
- name: Set up pnpm
# Avoid the standalone @pnpm/exe binary, which has no working Intel
# macOS build for this pnpm line.
uses: pnpm/action-setup@v5
with:
version: 10.12.4
standalone: false
- name: Set up Node.js 24
uses: actions/setup-node@v7
with:
node-version: '24.x'
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Audit production dependencies
run: pnpm audit --prod --audit-level=high
- name: Build
run: pnpm run build
- name: Validate generated bundles
run: pnpm run validate:build
- name: Validate npm package contents
run: pnpm run validate:npm-package
- name: Smoke test npm package
run: pnpm run smoke:npm-package
- name: Typecheck
run: pnpm run typecheck
- name: Run tests with coverage
run: pnpm run test:coverage
- name: Validate Bugbot quality benchmark
run: pnpm run eval:bugbot
- name: Upload coverage to Codecov
uses: codecov/codecov-action@v6
# Coverage reporting is advisory; Codecov v6 requires gpg even when
# fail_ci_if_error is false, and the internal macOS runner may not have it.
continue-on-error: true
with:
files: ./coverage/lcov.info
disable_search: true
fail_ci_if_error: false
token: ${{ secrets.CODECOV_TOKEN }}
verbose: true
- name: Lint
run: pnpm run lint
- name: Validate documentation
run: pnpm run validate:agent-docs
- name: Validate documentation assets
run: pnpm run validate:docs-page
- name: Validate documentation contract
run: pnpm run validate:documentation
- name: Validate workflow contract
run: pnpm run validate:workflows
- name: Validate product specification catalog
run: pnpm run validate:specifications
- name: Validate Git diff
run: git diff --check